¡¶Î¬ËûÃü¡·ÖðÈÕ°²È«¼òѶ20181121

°ä²¼¹¦·ò 2018-11-21
1¡¢¿¨°Í˹»ù°ä²¼2019ÄêÍøÂçÍþвÇ÷ÏòµÄÔ¤²â»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¿¨°Í˹»ù³¢ÊÔÊÒ°ä²¼¶Ô2019ÄêÍøÂçÍþвÇ÷ÏòµÄÒ»¸öÔ¤²â·ÖÎö£¬ÖØÒªÄÚÈÝÔ̺¬£º»òÐí²»»áÔÙ·¢ÏÖ¸ü¶àµÄ´óÐÍAPT×éÖ¯£»ÍøÂçÓ²¼þÓëÎïÁªÍøÍþв½«»á²»ÐݼÓÇ¿£»Óë±í½»ºÍÕþÖÎÓйصĹ«¿ª±¨³ð£»¶«ÄÏÑǺÍÖж«µØÓò»òÐí»á³öÏÖ¸ü¶àµÄ¹¥»÷×éÖ¯£»£¨Ring -£©È¨ÏÞ£¬±ÈRing 0¸ü¸ßµÄȨÏÞ£»×îÊÜÓ­½ÓµÄϰȾý½é-´¹µö£»»ò½«³öÏÖ¸ü¶àÀàËÆ¡°°ÂÔ˱÷³ý½¢¡±µÄ¹¥»÷£»¹©¸øÁ´¹¥»÷½«³ÖÐø£»Òƶ¯¶ñÒâÈí¼þ²»»á³öÏÖ´ó·¢×÷£¬µ«¸ß¼¶¹¥»÷Õß»á³ÖÐøÑ°ÕÒÈëÇÖÉ豸µÄ²½Öè¡£

  

 Ô­ÎÄÁ´½Ó£º

https://securelist.com/kaspersky-security-bulletin-threat-predictions-for-2019/88878/


2¡¢FireEye°ä²¼¹ØÓÚAPT29µÄд¹µö»î¶¯µÄ·ÖÎö»ã±¨

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



2018Äê11ÔÂ14ÈÕFireEye¼ì²âµ½Õë¶Ô¶à¸öÐÐÒµµÄ20¶à¸ö¿Í»§µÄÐÂÕë¶ÔÐÔ´¹µö¹¥»÷£¬º­¸ÇÖǿ⡢·¨ÂÉ»ú¹¹¡¢Ã½Ìå¡¢ÃÀ¹ú¾ü·½¡¢Í¼Ïñ¡¢ÔËÊä¡¢ÔìÒ©¡¢µ±¾Ö»ú¹¹ÒÔ¼°¹ú·À³Ð°üÉ̵È¡£ÕâЩ´¹µö¹¥»÷ÀûÓüÙ×°³ÉÀ´×ÔÃÀ¹ú¹úÎñÔºµÄ´¹µöÓʼþ£¬ÊÔͼ´«²¼Cobalt Strike Beacon¡£Æ¾¾Ý¶ÔÆäTTPµÄ·ÖÎö£¬Æä±³ºóµÄ¹¥»÷×éÖ¯ÒÉΪAPT29¡£

  

Ô­ÎÄÁ´½Ó£º

https://www.fireeye.com/blog/threat-research/2018/11/not-so-cozy-an-uncomfortable-examination-of-a-suspected-apt29-phishing-campaign.html


3¡¢ÃÀ¹ú´ó³ÇÊÐÈËÊÙ±£ÏÕ¹«Ë¾Òâ±íй¶²¿Ãſͻ§µÄÓ×ÎÒÐÅÏ¢

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ƾ¾Ý¼ÓÀû¸£ÄáÑÇÖݰ䲼µÄÊý¾Ýй¶֪ͨ£¬ÃÀ¹ú´ó³ÇÊÐÈËÊÙ±£ÏÕ¹«Ë¾£¨MetLife£©ÓÚ10ÔÂ18ÈÕÒâ±íй¶Á˲¿Ãſͻ§µÄÓ×ÎÒÐÅÏ¢£¬ÕâЩÐÅÏ¢ÒÔ¸½¼þµÄ´ó¾Ö±»·¢Ë͸øÓëMetLifeºÏ×÷µÄBenefits Administrator£¨¸£ÀûÖÎÀíÔ±£©£¬²¢Ëæºó±»É¾³ý¡£ÓйØÊý¾ÝÔ̺¬¿Í»§µÄÉç±£ºÅÂë¡¢±£ÏÕÁìÓò¡¢µ®ÉúÈÕÆÚ¡¢ÐÔ±ðºÍµØÖ·µÈ¡£Ö»¹ÜÒÔΪ¿Í»§µÄPII²¢Ã»ÓÐÊܵ½ÇÖº¦£¬µ«MetLifeÒÀÈ»¾ö¶¨ÎªÊÜÓ°ÏìµÄ¿Í»§ÌṩһÄêµÄÐÅÓþ¼à¿Ø·þÎñ¡£

  

Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/data-leak-incident-reported-by-fortune-500-metropolitan-life-insurance-company-523865.shtml


4¡¢OSIsoft LLCÔâºÚ¿ÍÈëÇÖ£¬ËùÓÐÓòÕÊ»§µÄµÇ¼ʹ´¦¶¼±»ÇÔÈ¡

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


11ÔÂ16ÈÕOSIsoft LLCÏò¼ÓÖÝÖݼì²ì³¤°ì¹«ÊҰ䲼֪ͨ³Æ¸Ã¹«Ë¾Ôâµ½ºÚ¿ÍÈëÇÖ£¬Ô̺¬¹«Ë¾Ô±¹¤¡¢ÕÕ·÷¡¢ÊµÏ°ÉúºÍµÚÈý·½³Ð°üÉ̵ÄÊý¾ÝÒÉй¶¡£OSIsoftÊÇʵʱÊý¾ÝÖÎÀíÈí¼þPI SystemµÄ¿ª·¢ÉÌ£¬¸ÃÈí¼þ±»³¬¹ý65%µÄ²Æ¸»500Ç¿¹¤Òµ¹«Ë¾ËùʹÓá£OSIsoft°µÊ¾·¢ÏÖÁËÉæ¼°29Ì¨ÍÆËã»úºÍ135¸öÕË»§µÄÍ´´¦ÍµÇԻµÄÖ±½ÓÖ¤¾Ý£¬½ø¶øµÃ³ö½áÂÛËùÓеÄOSIÓòÕË»§¶¼Òѱ»Í»ÆÆ¡£¼øÓÚ¸ÃÊý¾Ýй¶ÊÂÎñµÄÑϳÁÐÔ£¬OSIsoftÔÚ¶à¸ö°²È«·þÎñÉ̵ÄÔ®ÊÖϽøÐе÷²é¡£

 

 Ô­ÎÄÁ´½Ó£º

https://news.softpedia.com/news/osisoft-breached-all-domain-accounts-emails-and-passwords-assumed-compromised-523863.shtml


5¡¢TalkTalkÈëÇÖÊÂÎñÖеÄÁ½ÃûºÚ¿Í±»ÅÐÈëÓü£¬ÔøÔì³É7700ÍòÓ¢°÷µÄËðʧ

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


¾ÝÓ¢¹úÖðÈÕÓʱ¨±¨Â·£¬Á½ÃûºÚ¿ÍÒò2015ÄêµÄTalkTalkÈëÇÖÊÂÎñ±»ÅÐÈëÓü¡£TalkTalkÊÇÓ¢¹ú×î´óµÄµçÐŹ«Ë¾Ö®Ò»£¬ÕâÁ½ÃûºÚ¿Í¹²ÇÔÈ¡Á˳¬¹ý15.6ÍòÃû¿Í»§µÄÓ×ÎÒÐÅÏ¢¡¢²ÆÕþÐÅÏ¢¼°ÐÅÓþ¿¨ÐÅÏ¢£¬Ôì³ÉµÄËðʧ´ï7700ÍòÓ¢°÷¡£ÏÖÄê23ËêµÄMatthew HanleyºÍ21ËêµÄConnor AllsoppÈÏ¿ÉÁËÓйØÖ¸¿Ø£¬²¢±ðÀë±»Åд¦12¸öÔºÍ8¸öÔµÄÓÐÆÚͽÐÌ¡£

 

 Ô­ÎÄÁ´½Ó£º

https://thehackernews.com/2018/11/talktalk-data-breach.html


6¡¢Adobe°ä²¼Flash Player´¹Î£°²È«¸üУ¬½¨¸´Ò»¸öËÁÒâ´úÂëÖ´Ðзì϶

GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±¾ÖܶþAdobeÕë¶ÔFlash Player¸ßΣ·ì϶£¨CVE-2018-15981£©°ä²¼´¹Î£°²È«¸üС£¸Ã·ì϶ÊÇÒ»¸öÀàÐÍ»ìºÏÃýÎ󣬿ɵ¼Ö¹¥»÷ÕßÔÚÓû§²»ÖªÇéµÄÇé¿öÏÂÖ´ÐÐËÁÒâ¶ñÒâ´úÂë¡£¸Ã·ì϶ӰÏìÁËWindows¡¢macOS¡¢LinuxºÍChrome OSµÈƽ̨ÉϵÄFlash Player 31.0.0.148¼°¸üÔçµÄ°æ±¾¡£½¨ÒéÓû§¾¡¿ì¸üÐÂÖÁ°æ±¾31.0.0.153¡£

 

 Ô­ÎÄÁ´½Ó£º

https://threatpost.com/critical-adobe-flash-bug-impacts-windows-macos-linux-and-chrome-os/139264/


ÉêÃ÷£º±¾×ÊѶÓÉGA»Æ½ð¼×άËûÃü°²È«Ó××é·­ÒëºÍÕû¶Ù